Source: OJ L, 2024/436, 2.2.2024 · Consolidated textCurrent language: EN
- Digital services act
Delegated acts
- Performance of independent audits
Article 5 Cooperation and assistance between the audited provider and the auditing organisation
At a time agreed with the auditing organisation, and in any event prior to the performance of any audit procedure, the audited provider shall transmit to the selected auditing organisation at least the following information:
a description of the internal controls put in place with respect to each audited obligation and commitment, including related indicators and all present and historical measurements, and benchmarks used by the audited provider to assert or monitor compliance with the audited obligations and commitments, as well as any supporting documentation;
its preliminary analysis of inherent and control risks, where the audited provider has performed such an analysis, and any supporting documentation;
information about any relevant decision-making structures, competences of departments of the provider, including the compliance function pursuant to Article 41 of Regulation (EU) 2022/2065, relevant IT systems, data sources, processing and storage, as well as explanations of relevant algorithmic systems and their interactions.
The audited provider shall grant the auditing organisation, without undue delay, access to all data necessary for the performance of the audit, including personal data, documentation, information on procedures and processes, and to the information technology systems, testing environments, personnel and premises of that provider, and any relevant sub-contractors.
The audited provider shall make all necessary resources available and provide the auditing organisation with the assistance and explanations necessary for the auditing organisation to analyse the relevant information and to carry out tests, including where the information requested by the auditing organisation in accordance with Article 37(3) of Regulation (EU) 2022/2065 is held by a third-party contracted by the audited provider.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
control risk
Definition
recipient of the service
Definition
audit evidence
Definition
audit risk
Definition
audit procedure
Definition
auditing organisation
Definition
information society service
Definition
audited provider
Definition
detection risk
Definition
misstatement
Definition
intermediary service
- a ‘mere conduit’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, or the provision of access to a communication network;
- a ‘caching’ service, consisting of the transmission in a communication network of information provided by a recipient of the service, involving the automatic, intermediate and temporary storage of that information, performed for the sole purpose of making more efficient the information's onward transmission to other recipients upon their request;
- a ‘hosting’ service, consisting of the storage of information provided by, and at the request of, a recipient of the service;
Definition
audited obligation or commitment
Definition
inherent risk
Definition
substantive analytical procedure
Definition
online platform
Definition
online search engine
Definition
internal control
Definition
audited service
Definition
test